Service rules
Terms of use, privacy and the AML notice on one page. Each is also available on its own.
Terms of use
Effective 2026-09-29 · as its own page
CORE (co-re.io) is operated by ТОО «KORE FINANCE», Astana, Kazakhstan. By using the service you accept these terms.
What CORE does
CORE compares the rates of several external exchange providers, creates the exchange order with the chosen one, and shows you its status.
CORE does not receive or hold your coins, is not a party to the exchange, and does not exchange them itself. An external provider runs the exchange and is recorded on the deal. Your deposit goes to them directly.
How to create an exchange
- choose the coins, networks and amount. The rate and the calculation work without registration;
- enter the payout address, a memo if your wallet or exchange requires one, and a refund address if you want one;
- tick your acceptance of these rules and of the AML, KYC and KYT policy. Without it no exchange is created;
- once it is created you get an exchange number, a deposit address and a deadline. The number opens the exchange page with the current status.
The provider's terms
The provider running your exchange has its own terms. Pressing the confirm button accepts them; we record that acceptance and its version. We name the provider before you confirm where its terms require it, and on your request after the exchange.
The provider may ask for documents, pause the exchange, or send the coins back less the network fee. Those decisions are theirs, not CORE's.
What you check
Blockchain transactions are irreversible. A sent transfer cannot be recalled.
- the payout address and its network - sending to the wrong network is irreversible and the coins are lost;
- the memo or tag, if your wallet or exchange requires one;
- the refund address - it is optional, but without it a refund has to be sorted out with the provider by hand.
Rate and amount
The rate floats. The amount you see is the provider's estimate at the time of the request. The final amount is set when the provider receives your deposit and may differ.
CORE adds no markup on top of the provider's rate. We are paid by the provider, and that is already inside their rate.
The rate is not fixed. The page shows until when the offer on it is valid; after that the offer has to be refreshed. When the exchange is created we ask the provider for a fresh offer.
Paying for the exchange
Send the coin to the deposit address on the network and in the amount shown on the exchange page, before the deadline shown there.
After the deadline, send nothing to this address: create a new exchange for a new transfer. An exchange whose deposit never arrived closes as expired 72 hours after the deadline.
A deposit sent after the deadline or in a different amount is handled by the provider under its own terms: it runs the exchange at a new rate or returns the coins. Write to us with the exchange number and we pass the question to the provider.
Timing and payout
The provider sends the payout to the payout address in the exchange once the deposit has been received and confirmed by the network. The payout amount is set by the rate at that moment.
CORE does not promise how long an exchange takes: that depends on the networks and on the provider's processing. The current stage is shown on the exchange page.
Any conditions that depend on the client's country are set by the provider in its own terms.
Questions after paying
Write to us from the exchange page: the exchange number is added to the request for you, and no account is needed. The answer appears there, and also by email if you have an account.
You can also write to business@co-re.kz with the exchange number.
If something goes wrong
- a wrong payout address, network or memo in the exchange: a blockchain transfer is irreversible. If the payout has not been sent yet, write to us at once and we ask the provider to stop the exchange. The outcome depends on the provider;
- a deposit on the wrong network, in the wrong coin, or without a memo the deposit address requires: only the provider can return such coins, and only where it is technically possible. Send us the exchange number and the transaction hash and we pass the request to the provider;
- an exchange paused for a check: the steps are in the AML, KYC and KYT policy;
- a network or provider outage: timings shift, and the status on the exchange page changes when the provider reports a new one. Coins the provider returns arrive at the refund address.
CORE works with cryptocurrency only: no bank account takes part in an exchange.
We help you reach the provider and follow up on the answer. CORE cannot cancel a sent transfer.
Personal data
What data we keep, for how long and why is set out in the Privacy policy.
AML, KYC and KYT
The provider runs the checks under its own rules. How this works, and what to do if an exchange is held, is set out in the AML, KYC and KYT policy.
Refusal of service
We may refuse an exchange or suspend access - in particular where an account is marked blocked, or on clear signs of unlawful use.
Responsibility
CORE is responsible for its part: comparing offers, creating the order, recording the provider on the deal, and showing the status. Execution, payout and any deductions are the provider's responsibility under its own terms.
CORE is not responsible for coins lost to a wrong address, a wrong network, a missing memo, or the provider's actions.
Changes
We may change these terms. The effective date is shown above; continuing to use the service after a change accepts the new version.
Privacy policy
Effective 2026-09-28 · as its own page
Data is processed by ТОО «KORE FINANCE», Astana, Kazakhstan.
What we store
- exchange data: assets and networks, amounts, the payout address, the refund address if you gave one, the memo, status and timestamps;
- your email - only if you created an account;
- saved addresses - only the ones you chose to keep in your account: the name, coin, network, address and memo. Delete them in your account under "Addresses";
- support conversations: the subject and the message text;
- the provider's responses about your exchange - encrypted;
- your IP address - to rate-limit requests and keep bots out. For that it is kept as a request counter and is not tied to your exchange;
- the IP address and browser User-Agent an exchange was created from, and your acceptance of the exchange rules and the AML, KYC and KYT policy with their versions. They are recorded with the exchange to show on what terms and from where it was created. Only the service can read them; they are not shown in your account or in the operator console.
Cookies
Without asking, only the ones the site cannot work without. There is no analytics or advertising cookie.
Language (core_locale) - one year. Sign-in session - until you sign out.
Theme (core_theme) - one year, only if you picked the light or dark theme yourself. It holds only that choice; without it the site follows your device setting.
Time zone (core_tz) - one year. Your browser sets it, not the server: some executors require a time zone alongside the request, and without this cookie they simply do not take part in the comparison. The zone travels nowhere except that request.
Account recovery (core_recovery_grant) - 15 minutes, and only while you are following a recovery link from an email. It proves the email was opened by you, and expires on its own.
Partner tag (core_ref) - 30 days, only if you arrived through a partner link and agreed to it. If you arrived from the BestChange exchange monitor, it has no end date: the tag is set for 400 days, the longest browsers keep one, and set again on every visit. It holds the partner's code so the exchange can be credited to them, is unreadable to page scripts, and contains nothing about you. Without consent the tag is not stored: an exchange started from the same link during this visit is still credited to the partner, a later one is not.
Your choice (core_consent) - six months. It holds only the answer about the partner tag, no identifier. Change or withdraw consent under "Cookie settings" in the site footer: withdrawing deletes the tag, exchanges already created are not changed.
Addresses saved "only on this device" are not cookies: they sit in your browser's storage and are not stored on our server. Delete them in your account or by clearing site data.
Any of them can be deleted in your browser: the site keeps working, it will just detect your language and zone again, and the partner tag will be gone.
What we do not do
- we run no analytics and no trackers: there is no Google Analytics, no Metrika, no pixels, nothing of the kind on this site;
- we do not verify identity (KYC) and do not ask you for documents;
- we do not sell or share your data for advertising.
Who we share with, and why
- the exchange provider - what it needs to execute: the pair, the amount, the payout and refund addresses. Some providers also receive the IP address, User-Agent and time zone the exchange is created from, where their terms require it;
- the contractors that keep the service running: hosting, the database and account sign-in, email delivery, bot protection on forms. They process data only on our instructions and only for those tasks;
- the messenger our operator receives service alerts in: exchange and ticket identifiers only, never your messages, amounts or addresses;
- government authorities - only where the law or an official request requires it; we do not disclose data on our own initiative.
An account is optional
Exchanging works without registration. Without an account we do not have your email, and the exchange's own link is the only access to it - keep it and do not pass it to anyone.
Protection
Provider secrets and raw provider responses are stored encrypted. Exchange data is not readable directly by anonymous or ordinary signed-in users; access belongs to the service and the operator.
We never ask for a seed phrase or a private key. Neither we nor the provider needs them.
Retention
We keep exchange data, including the IP address and User-Agent it was created from, for at least five years after the exchange is completed: the rules of exchange monitors and record-keeping require it. Accounts and conversations are kept while the account exists.
Your rights
You can ask what data we hold about you and ask us to correct or delete it, where that does not conflict with our record-keeping duties. Write to business@co-re.kz - you do not need an exchange for this.
AML, KYC and KYT policy
Effective 2026-09-29 · as its own page
CORE is non-custodial: we do not receive or hold client coins. An external provider runs the exchange; it is recorded on the deal and named on your request.
Who performs the checks
Source-of-funds screening and address checks against sanctions lists and risk databases (AML/KYT) are performed by the provider running your exchange, under its own rules. Both the deposit and the payout address may be checked.
CORE does not verify identity (KYC) and does not request documents on its own initiative. If the provider needs documents, the request comes from it directly or through support for your exchange.
What CORE checks before creating an exchange
- the payout address matches the chosen network;
- a memo or tag is present where the asset is not credited without one;
- the account is not marked blocked.
What the provider may do
The provider may pause the exchange, ask for documents, or send the coins back less the network fee. This is stated in the terms you accept on confirmation and reflected in the exchange status.
If an exchange is held
While the provider checks an exchange, the status on the exchange page stops moving or shows that more information is needed.
- do not send the deposit again and do not create a new exchange for the same coins;
- write to support from the exchange page: the exchange number is added to the request for you;
- answer the provider's request if one arrives. It may ask you to confirm the source of funds or your identity;
- give support a refund address if the exchange had none: it is needed if the provider decides to return the coins.
CORE contacts the provider with its order number, passes your answers on, follows the decision and tells you what it is. The decision to run the exchange, return the coins or hold them is the provider's, and CORE cannot overturn it.
Returns and holds
If the provider declines an exchange, it returns the coins to the refund address under its own terms, usually less the network fee. If it holds funds because the law or its own rules require it, the procedure and timing are its own.
CORE never holds client coins, so CORE does not pay out of its own funds any amount a provider holds or does not return. We help you pursue a return: we pass your requests and documents to the provider and tell you its answers.
Prohibited use
The service must not be used for money laundering, sanctions evasion, or any unlawful operation. We may refuse service and block access.
Questions
For questions about checks on a specific exchange, write to support from that exchange's page or to business@co-re.kz with the exchange number.